Cloud-based data platform Snowflake has introduced new security measures following a series of cyberattacks affecting high-profile customers such as Santander Bank and Neiman Marcus. As of October 2024, multifactor authentication (MFA) will be enabled by default for all new accounts, and a minimum requirement of 14 characters for passwords applies.
Important findings
- Introduction of multifactor authentication for new accounts from October 2024.
- Minimum requirement of 14 characters for passwords, no reuse of passwords.
- Security measures in response to cyberattacks in June 2024.
Background of the attacks
In June 2024, Snowflake became the target of a series of cyberattacks in which attackers gained access to customer data through compromised third-party environments. The attackers used stolen credentials to download files from Snowflake customers and demanded a $5 million ransom for the deletion of the stolen data.
The attacks were identified as “credential stuffing,” in which attackers reuse usernames and passwords derived from other services or data leaks. An analysis by Google Mandiant traced the attacks to a financially motivated threat group known as UNC5537.
New security measures
To improve security, Snowflake announced the following measures:
- Multifactor Authentication (MFA): Starting October 2024, MFA will be enabled by default for all human users in new Snowflake accounts.
- Longer passwords: Passwords must be at least 14 characters long and must not be reused.
- OAuth Token Verification: Users are encouraged to use OAuth tokens or key pairs to connect to external data visualization tools.
Response to Attacks
After the attacks in June 2024, Snowflake introduced some security features in July 2024 to strengthen the use of MFA. These include:
- The ability for administrators to require strong authentication for all users.
- Free tools to monitor stolen credentials and overprivileged accounts.
Snowflake has stated that these measures are in line with the Cyber Security and Infrastructure Security Agency’s Secure By Design Pledge, which aims to design products with better integrated security.
Conclusion
Snowflake’s new security measures are an important step towards improving data security in the cloud. With cyberattack threats on the rise, it is critical that organizations take proactive measures to protect their systems and data. The introduction of MFA and the requirements for longer passwords are part of this strategy to ensure the security of customers.
Sources
- Breach-Weary Snowflake Moves to MFA, 14-Character Passwords, BankInfoSecurity.



